Reference

How wwtoto2 wap Handles Your Personal Data

Your privacy on wwtoto2 wap is a structured commitment, not an afterthought — every piece of information you share when opening an account or transacting via DANA, OVO…

Account data kept secureDANA, OVO, GoPay & QRIS transactions protectedYour right to access or erase dataJakarta & Surabaya accounts coveredRetention periods clearly stated
wwtoto2 wap How wwtoto2 wap Handles Your Personal Data
PRIVACY CONTACT PATHS

How to Reach Us About Your Privacy Rights

Team online

Live Chat — Privacy Requests

Our privacy team monitors the live chat channel daily from 08:00 to 23:00 WIB. Start a chat, select 'Account & Privacy' from the topic menu, and a dedicated agent will handle your data request within one business hour during those hours.

Email — Data Access & Deletion

Send a written data access or deletion request to our privacy inbox at [email protected]. Include your registered account ID and the nature of your request. We aim to send a confirmation within 24 hours and complete the action within 30 calendar days.

Account Settings — Cookie & Session Controls

Log in, navigate to Settings › Privacy, and you can toggle non-essential cookies off, review which device sessions are active, and revoke third-party analytics consent at any time without contacting support — the change takes effect immediately.

DATA HANDLING PRACTICES

Six Ways We Protect and Manage Your Information

We approach data handling through six operational practices that cover your account from the moment you register through to any deletion request you submit.

Encrypted Data Storage

All personal and payment data — including your DANA and OVO transaction history — is stored with AES-256 encryption at rest. Access to the underlying database is restricted to authorised operations staff only, logged and audited on a monthly cycle.

Cookie Management

We set two categories of cookies: strictly necessary session cookies that keep you logged in, and optional analytics cookies that measure page load performance. You can disable the analytics category from Settings › Privacy without affecting your account or wallet access.

Account Security Logs

Every login event, password change, and withdrawal request tied to your account is logged with a timestamp and device fingerprint. You can view a 90-day activity log from Settings › Security to spot any access you did not initiate and flag it to our team immediately.

Data Retention Schedule

Transaction records tied to GoPay and QRIS payments are kept for five years to meet financial audit standards. Profile data — your name, email and preferences — is purged from live servers within 30 days after a verified deletion request is approved by our privacy team.

Third-Party Data Sharing

We share data with third parties only when required to process your payment (e.g. routing a DANA transfer) or when required by applicable authority under local law. We do not share data for advertising purposes, and no profiling of your activity is sold externally.

Your Right to Request Changes

You can request a copy of the data we hold about you, ask us to correct inaccurate profile information, or submit a full deletion request at any time via email or live chat. Rights may vary depending on local law applicable to your region of access.

What You Ask About Our Privacy Policy

The questions below cover the most common concerns we hear from people in Jakarta, Surabaya and across Indonesia who want to understand how their data is handled before opening an account or making a deposit.

We collect your name, email address, date of birth, and preferred payment method — for example DANA or OVO. We also log your device type and IP address at login to protect your account from unauthorised access. No more than what is operationally necessary.

We store a reference record of each transaction — amount, timestamp, and payment channel (DANA, GoPay, OVO or QRIS) — but we do not store your full wallet credentials or PINs. Payment authentication happens directly through the respective payment provider's encrypted gateway.

Transaction-level data is retained for five years for audit compliance. Profile data such as your name and email is deleted from live systems within 30 days after you submit and we verify a deletion request via email or live chat during our 08:00–23:00 WIB support window.

Yes. Email [email protected] with your registered account ID and the subject line 'Data Access Request'. We will compile and send you a structured copy of your profile and transaction data within 30 calendar days of verifying your identity. This right depends on local law.

We do not sell or license your data to advertisers or external marketing networks. Data is shared with third parties only to process your payment transactions or when mandated by relevant authority under local law. Your activity on our platform is not profiled for external ad targeting.

Log in and go to Settings › Privacy. You will see a toggle for optional analytics cookies; switching it off disables performance tracking immediately. Strictly necessary session cookies cannot be turned off without logging out, as they keep your account session active and secure.

Go to Settings › Security to view your 90-day login history. If you see an unfamiliar device or location, change your password immediately and contact our live chat team — available 08:00–23:00 WIB — selecting 'Account & Privacy'. We will investigate and flag the session within one business hour.